PREDICATIVE TOPOSES 
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Abstract. Wo explain the motivation for looking for a predicative analogue of the notion of 
a topos and propose two definitions. For both notions of a predicative topos we will present 
the basic results, providing the groundwork for future work in this area. 



1. Introduction 

Topos theory is a highly successful chapter in the categorical analysis of constructive logic. 
Originally toposes were invented by Grothendieck with the aim of proving the Weil conjectures 
in algebraic geometry. Later it became clear that these Grothendieck toposes have a rich internal 
logic, which led Lawvere and Tierney to formulate the notion of an "elementary topos" . For 
quite some time, the only examples of such elementary toposes that people knew about were 
Grothendieck toposes and the free topos. This changed when Martin Hyland discovered the 
effective topos at the beginning of the eighties. More recently, people have discovered Dialectica 
toposes whose internal logic is related to various functional interpretations. As a result, we have 
a common framework in which to study topological, sheaf and Kripke models (because these 
are special cases of Grothendieck toposes) as well as realizability and functional interpretations. 

But the power and expressiveness of the internal logic of a topos also creates a certain 
emharras de richesse. Indeed, it is far stronger than what most constructive mathematicians 
are willing to use in their work. Nowadays, most constructivists point to systems like Martin- 
Lof's Type Theory (MLTT) [26] or Peter Aczel's constructive set theory CZF [1] as providing 
the kind of system in which they want their work to be formalisable. These systems are much 
weaker, however, than the internal language of a topos, which is a form of full higher-order 
arithmetic (if we use topos to mean elementary topos with natural numbers object, as we will 
do in this paper). 

The key difference is that MLTT and CZF are systems which are (generalised) predicative; 
this means that, although they may accept a wide variety of inductively defined sets, they do 
not include the powerset axiom. In contrast, the internal language of a topos is impredicative, 
due to the presence of a subobject classifier and power objects more generally. 

This has led people to wonder whether there could be a kind of "predicative topos" : a topos- 
like structure whose internal language would be closer to the formal systems constructivists 
actually use. Ideally, one could develop for these predicative toposes an equally rich and 
interesting theory, which would be closer in spirit to constructive mathematics as it is practised. 

The first proposals for such a notion of a predicative topos were put forward by Moerdijk 
and Palmgren (see their notions of a IIM^-pretopos i29j and a stratified pseudotopos [30]). But 
before we go into this, it is good to first get an idea of what properties one would like predicative 
toposes to have. A list of desiderata would probably include: 
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(1) A predicative topos should at least be a locally cartesian closed pretopos with natural 
numbers object. 

(2) Every topos should be a predicative topos. 

(3) The setoids in MLTT should form a predicative topos. 

(4) The sets in CZF should form a predicative topos. 

(5) Predicative toposes should be environment in which one can do formal topology. 

(6) Predicative toposes should be closed under internal sheaves and realiz ability. 

(7) There should be interesting examples of predicative toposes that are not toposes. 

It might be good to make a few remarks concerning these requirements. 

Ad 3: Because MLTT is an intensional theory, the "sets" one works with are not really 
the types, but types together with an equivalence relations (i.e., setoids). This is related 
to the distinction that Bishop makes between sets and presets. So we try to capture 
the categorical properties of the sets rather than the presets (see [32] for a discussion 
of this point). 

Ad 5: Recently a lot of constructivists have worked on formal topology. Essentially, 
this is locale theory in a predicative metatheory. The idea behind point (5) is that 
predicative toposes should stand to formal spaces in the same way as toposes stand 
to locales. That means both that one should be able to do formal topology inside 
predicative toposes and that one should be able to take sheaves over a formal space 
internally to a predicative topos and again get a predicative topos. 

Ad 6: In the same way, we want to be able to take sheaves or do realizability inside a 
predicative topos and again get a predicative topos back. As a result, sheaves and 
realizability should not only be model constructions giving rise to predicative toposes, 
but actually be closure properties of the class of predicative toposes. 

It turns out that it is very hard, indeed impossible, to satisfy all of these desiderata. 

First of all, there are two dilemmas. The first dilemma is how many inductively defined 
sets one adds to one's notion of a predicative topos. It is often said that MLTT is an open 
framework to which one may add as many inductively generated sets as one wants. But we 
need to fix something in order to get going. In CZF, however, there are very few inductively 
generated sets. In this connection, Peter Aczel proposed to add another axiom to CZF (the 
Regular Extension Axiom, or REA). The question is to which extent we follow him in this. 

The second dilemma is how much choice we add to our notion of a predicative topos. Most 
constructivists are willing to countenance certain forms of choice; and, as we will see, one seems 
to be compelled to use some amount of choice if one can no longer reason impredicatively. In 
a general topos, however, only very few choice principles hold. 

These dilemmas turn into a real problem if one starts to do formal topology. The general 
notion of a formal space is really too ill-behaved: in a predicative setting only those formal 
spaces that are set-presented (in Peter Aczel's terminology) behave well. For example, working 
in CZF, one need not get a model of CZF if one takes sheaves over a formal space that is not 
set-presented (see [l8 l [15 ] ). 

On the other hand many formal spaces cannot be shown to be set-presented inside CZF; 
this includes formal Baire space (see [9]). Formal Baire space is an example of an "inductively 
generated formal space" [H] and to show that these are set-presented we have to go beyond 
CZF. So if we insist that internally to a predicative topos we should be able to prove that 
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"inductively generated formal spaces are set-presented", we have to drop requirement (4); and, 
indeed, that is what we will do. 

As it turns out, proving the statement "inductively generated formal spaces are set-presented" 
seems to be one of those things for which we need to add some inductively generated sets and 
choice. Let us take the inductively generated sets first. 

What kind of inductively defined sets would one like to add? The obvious choice seems to 
be the W-types of MLTT. In [^H], Moerdijk and Palmgren observe that these can be captured 
categorically as initial algebras for polynomial functors, and adding these to a locally cartesian 
closed pretopos leads to their notion of a nW^-pretopos. 

Unfortunately, we still seem to need some choice. We have not been able to prove that 

(i) inductively generated formal spaces are set-presented, 

(ii) taking sheaves over a set-presented formal space gives you a category which again has 
W-types 

without some form of choice (see [7] in connection with (ii)). We do not have proofs that these 
results cannot be proved internally to a IIVF-pretopos (that would probably be very hard) , but 
we are sceptical that it can be done. 

So what form of choice do we add? If we would follow the lead of MLTT again, we would 
postulate the existence of enough projectives (because that is what happens in the category of 
setoids). That would allow us to prove the two theorems above, but it would not be compatible 
with desideratum (6): the existence of enough projectives is not stable under sheaves. 

For solving precisely this issue, Moerdijk and Palmgren introduced in i3(T an axiom they 
called the "Axiom of Multiple Choice" (AMC). We have renamed their axiom the "Strong 
Axiom of Multiple Choice" (SAMC), because there is a weaker axiom which does the job as 
well: we have decided to reserve the name "Axiom of Multiple Choice" for this weaker axiom 
(see m- 

As a result we have the following notion of a predicative topos: a IIVF-pretopos satisfying 
AMC. It turns out that in a predicative topos both (i) and (ii) are provable. In fact, these results 
do not only hold for formal spaces but for general sites; we will work this out in Section 8. (The 
results will look a bit different there: in fact, without a distinction between sets and classes as 
in CZF, it is hard to talk about formal spaces that are not set-presented: set-presentedness 
will become part of the definition.) 

nT4^-pretoposes that satisfy SAMC will be called strong predicative toposes. We have no 
clear preference as to what should be the "true" notion of a predicative topos: whether it should 
be the strong or the weak one. Right now, everything one wants to do with SAMC one can 
also do with ordinary AMC; but SAMC holds in all the examples we know of and its stability 
under various constructions may be easier to show due to its equivalence to a new axiom called 
RP (see Section 5). 

But one may object to both notions, because it is not clear that they satisfy requirement 
(2), saying that every topos should be an example; and, in fact, they do not, for AMC is not 
provable in higher-order arithmetic. It is not even provable in ZF, as we will show in Section 6 
(note that Rathjen and Lubarsky have shown the same for REA, see [35]). This might dismay 
topos theorists, but it should be kept in mind that: 
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• AMC follows from the axiom of choice, so is true in Sets. And because AMC will be 
stable under realizability and sheaves, it will hold in realizability and sheaf categories 
defined over Sets. 

• AMC could have certain desirable consequences, which are not provable in higher-order 
arithmetic. For example, in ZF it implies that every algebraic theory has free algebras, 
a result which is not provable in ZF proper (see Section 6). 

However, both our notions of a predicative topos satisfy all the other criteria in the list (all 
of them, apart from (2) and (4), that is). Essentially that is the upshot of [301 [SI ISl IZl IE] • But 
there the results are stated in the context of algebraic set theory and Aczel's constructive set 
theory CZF, which might not be congenial to everyone. Indeed, one of the main purposes of 
this paper is to explain these results in a more categorical language and make clear what is 
their relevance to predicative topos theory. We also collect important results from other sources 
hoping that this paper can act as a starting point and reference for future work in this area. 

But we do not only collect or restate old results; there will be some novel results as well. 
Concretely, these are: 

(1) We show that SAMC is equivalent to a new axiom, which we call RP. 

(2) We use this to show that SAMC is preserved by ex/reg-completion and realizability. 

(3) We show that AMC is unprovable in ZF. 

(4) We show that the subcountable objects in the effective topos and the ex/lex-completions 
of the categories of topological spaces and To'Spaces are examples of strong predicative 
toposes. 

(5) We show that (i) is provable in predicative toposes for general sites. 

The contents of this paper will be as follows. In Section 2 we will establish categorical 
notation and terminology and give a precise definition of the notion of a IIVF-pretopos. In 
Section 3 we will introduce both variants of the Axiom of Multiple Choice and in Section 4 we 
will introduce a reflection principle and show it is equivalent to SAMC. We will study AMC 
in the context of the classical set theory ZF in Section 5. In Section 6 we will give examples 
of predicative toposes and we will also discuss closure under realizability. Section 7 will be 
devoted to closure under sheaves and showing that (i) and (ii) hold in predicative toposes for 
general sites. Finally, to conclude our paper, we will indicate directions for future research in 
Section 8. 

2. Categorical preliminaries 

It will be the purpose of this section to establish the categorical terminology and notation 
that we will need. In particular, we define precisely the notion of a IIM^-pretopos. But first we 
recall some results from the theory of exact completions; these will become important because 
we will obtain most interesting examples of predicative toposes as exact completions. 

Definition 2.1. Let C be a category. A map f:B^Aisa cover, if the only subobject of 
A through which it factors is A itself. The category C will be called regular, if it has finite 
limits, every map factors as a cover followed by a mono, and covers are stable under puUback. 
A functor _F: C — >■ 2? will be called regular, if it preserves finite limits and covers. 

Definition 2.2. Let C be a category with finite limits. A subobject {ro,ri):R C X x X mC 
will be called an equivalence relation, if for any object A in C the induced map 

Hom(^, R) ^ Hom(A, X)^: f ^ (ro o /, n o /) 
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is injective and determines an equivalence relation on Hom(v4, X). A map q: X ^ Q will be 
called a quotient of the equivalence relation, if the diagram 

R ] X—^O 

ri 

is both a pullback and a coequaliser, in which case the diagram is called exact. It is called 
stably exact, when for any p: P !■ Q the diagram 

v*R t v*X-!-^P 

p'ri 

is also exact. The category C will be called exact, if it is regular and every equivalence relation 
fits into a stably exact diagram. 



Every category with finite limits can be turned into an exact category in a suitably universal 
way. More precisely, for any category with finite limits C there is an exact category Cex/iex 
(its ex/lex-completion) together with a finite limit preserving functor y:C — Cex/iex such that 
for any exact category T) precomposing with y induces an equivalence of functor categories 
between the finite limit preserving functors from C to V and the regular functors from C^x/iex 
to 2?. In addition, regular categories can be turned into exact categories, while preserving the 
regular structure: so for any regular category C there is an exact category Ci^x/reg (its ex/reg- 
completion) together with a regular functor y; C — > C^x/iex such that for any exact category T) 
precomposing with y induces an equivalence of functor categories between the regular functors 
from C to P and the regular functors from Cex/reg to V. For the purposes of this paper, we do 
not need to know how one constructs these completions (for that see but we do need to 

be able to recognise them. 

Definition 2.3. If X and Y are two objects in a category C, we say that Y is covered by X if 
there is a cover q:X—^Y. A functor F:C ^ V will be called covering, if every object D in T) 
is covered by one in the image of F . It will be called full on subobjects if every subobject of an 
object in the image of F is isomorphic to an object in the image of F. 

Definition 2.4. Let C be a regular category. An object P in C is a projective if every cover 

p: X >P splits. We will say that the category C has enough projectives if every object in C is 

covered by a projective. 

Proposition 2.5. Let C be a category with finite limits, V be an exact category and F:C V 
be a finite limit preserving functor. Then T) is equivalent to the ex /lex- completion of C via an 
equivalence which commutes with F:C ^ V and y.C ^ C^x/iex iff 

(1) F is full and faithful, 

(2) F is covering, 

(3) and the objects in the image of F are, up to isomorphism, the projectives in T>. 



Proof. See [13] . □ 

Proposition 2.6. Let C be a regular category, T> be an exact category and F:C ^ V be a 
regular functor. Then V is equivalent to the ex /reg- completion of C via an equivalence which 
commutes with F:C V and y.C ^ Cex/reg iff F is full and faithful, covering, and full on 
subobjects. 



Proof See [13]. 



□ 
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Corollary 2.7. Let C be a regular category and assume that C has enough projectives and the 
projectives in C are closed under finite limits (meaning that the limit of any finite diagram whose 
objects are all projective is again projective) . Then Proi{C)ex/iex o,'^d C^^jreg o-f^ equivalent, 
where Proj(C) is the full subcategory of C on the projectives. 

Proof. It is clear that the inclusion i<':Proj(C) Cex/reg is full and faithful, cartesian and 
covering. So we need to show that the objects in the image of F are, up to isomorphism, the 

projectives of Cex/reg- 

So suppose P is projective in Cex/reg- Since y:C — > C^x/reg is covering, there exists a cover 
yX — >■ P. Because P is projective, this cover splits and P must actually be subobject of yX. 
Since y is full on subobjects, P is isomorphic to some yQ with Q in C. This object Q has to 
be projective in C, because y is regular and full and faithful; so P is isomorphic to an object 
in Proj(C). 

Conversely, suppose Q is projective in C; we want to show that yQ is projective in Cgx/reg- 
So let q:X^ yQ be a cover. Since y is covering, we can cover X via some p: yA X. Since 
y is full, there is a map f: A ^ Q in C with yf — qp. It is not hard to see that / is a cover 
and therefore must have a section s:Q ^ A. Now qpys — y/ys = id, so q splits. □ 

We will now define the notion of a Iliy-pretopos. Before we can do that, we first need to 
define locally cartesian closed categories, polynomial functors and W-types. 

Definition 2.8. A category C which has all finite limits is called locally cartesian closed if for 
any map f:Y^X the pullback functor 

f*:C/X^C/Y 

has a right adjoint. This right adjoint is usually denoted 11^^. 

Alternatively we could say that a category is locally cartesian closed if it has all finite limits 
and all its slice categories are cartesian closed. 

Definition 2.9. Let /: B — ^ A be a map in a locally cartesian closed category C. The polynomial 
functor associated to / is the endofunctor 

Pf.C^^C/B^^C/A^^C, 

where E^i is the forgetful functor C/A — > C which only remembers the domain. 

The initial algebra for Pf, whenever it exists, is called the W-type associated to /. If all 
polynomial functors have initial algebras, we say that C has W-types. 

For more on these W-types, we refer to and [1]. 

Definition 2.10. A category which has all finite limits and finite sums which are disjoint and 
stable under pullback is called lextensive. A category which is both lextensive and exact is 
called a pretopos. 

Definition 2.11. A IIVF-pretopos is a locally cartesian closed pretopos having all W-types. 

When we write topos in this paper, we will always mean an elementary topos with natural 
numbers object. 

Tileorem 2.12. Every topos is a liW -pretopos. 
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Proof. It is well-known that every topos is a locally cartesian closed pretopos. The existence 
of W-types is Proposition 2.3.5 in [33] (see also [12] and [29]). □ 

3. The Axiom of Multiple Choice 



In this section we will introduce both variants of the Axiom of Multiple Choice (see also 
[SO] [8]). Before we do that, we first define covering and (strong) collection squares. 

Throughout this section we will work in a category £ which is locally cartesian closed, 
lextensive and regular. Such a category is in particular a Heyting category, which means that it 
has an internal logic which is a typed version of first-order intuitionistic logic with (dependent) 
product and sum types. We will often exploit this fact. Readers who need to know more about 
the internal logic we refer to [25] [21] . 



Definition 3.1. We call a square 




a covering square, if both p and the canonical map D — > B Xj\^ C are covers. When such a 
covering square exists with a map g on the left and / on the right, we say that g covers f and 
/ is covered by g. 

Remark 3.2. Note that the orientation is important for being a covering square, as the maps 
p and / play different roles. So being a covering square is really a property of an oriented 
square. To fix things, we will always draw covering squares in such a way that the property 
holds from "left to right" (as in the definition), instead of from "top to bottom". For (strong) 
collection squares the same convention will apply. 

Definition 3.3. A square as the one above will be called a collection square, if the following 
statement holds in the internal logic: for every c G C and cover e: E ^ Dc there is a c' G C 
with p{c) — p{c') and a map h: Dc' — !> Dc over B which factors through e. It will be called a 
strong collection square if h can be chosen to be a cover. 

Remark 3.4. In [Q we required collection squares to be covering as well. This turned out to 
be less convenient here, so we no longer make that part of the definition. But in case the square 
is covering the definition here agrees with the one in j8^, as the following lemma shows. 

Lemma 3.5. A covering square 

D—^B 




is a collection square iff the following statement holds in the internal logic: for all a G A and 
covers e: E ^ Ba there is a c G p~^{a) and a map t: Dc — t- E such that the triangle 




commutes. 
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Proof. An easy exercise in using the internal logic: suppose the square is a collection square 
and we are given a cover e: E ^ Ba- First, we find a c S C with p(c) = a, because p is a cover, 
and we pull back e along as in: 

Z — "-^E 



Since the square is collection, we find a c' € C with p{c') = p{c) = a and a map s: Dc' — >■ Z 
such that qcfs — qc'. Hence c' and t: — rs are as desired. 

Conversely, suppose we are given an element c £ C and a cover e: E ~» Dc- Put a: — p{c) 
and consider q^e: E — > Ba- We find an element c' ^ C with p(c') = a and a function s: Dc' — > E 
such that qc' = qc^s. Then c' and h: — es are as desired. □ 



We can now state the 

(Strong) Axiom of Multiple Choice: Every map f:Y^X fits into the right-hand 
side of a square which is both covering and (strong) collection. 

We will abbreviate the Axiom of Multiple Choice as AMC, and its strong version as SAMC. 
Clearly, SAMC implies AMC. (We believe that the converse fails. We do not have a proof, 
however, and we expect that finding one will be very difficult.) 

The Axiom of Multiple Choice is really a weak choice principle. As such, it is implied by 
related choice principles. We will discuss a few of them, following |30) . 

Definition 3.6. An object P is called a choice object, when for any cover Y ^ X and any 
arrow T x P ^ X, there exists a cover T' T and map T' x P Y such that the square 

T' X P > Y 



T X P >X 

commutes. An arrow f:Y ^ X is called a choice map, if it is a choice object in the slice 
category £/X. 

Since we are assuming that our base category £ is locally cartesian closed, an object P in 
f is a choice object iff the functor (— )^ preserves covers (see e.g. j2l])- This is the same as 
saying that the following scheme is valid in the internal logic of £ for any object X: 

(Vp G P) {3x G X) ip{p, x) ^ (3/ e XP) (Vp e P) ^(p, /(p)). 

For this reason choice objects are often called internal projectives, but we will not use this 
terminology here. 

Proposition 3.7. // every map f:B^Ain£is covered by a choice map, meaning that it fits 
into a covering square 

D—^B 

9 / 



with a choice map g on the left, then £ satisfies SAMC. 
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Proof. This is immediate using the internal logic: since g is a choice map, every cover q: E ^ Dc 
has a section (internally). □ 

Proposition 3.8. If £ has enough projectives and the projectives in £ are closed under pull- 
hacks, then every map in £ is covered by a choice map. Hence £ satisfies SAMC. 

Proof. If £ has enough projectives, then every map f-.B^Ais covered by a map between 
projectives g-.D^C: we choose C to be a projective cover of A and D to be a projective cover 
of C xa B. It is immediate that g is projective in £/C. But it is also a choice object in this 
category, because if projectives are closed under products, then every projective is automatically 
a choice object (that is easy to see); this applies to£/C, because we are assuming the projectives 
in £ to be closed under pullbacks and we know that C is projective. □ 



4. A REFLECTION PRINCIPLE 



In this section we introduce a reflection principle reminiscent of Peter Aczcl's Regular Ex- 
tension Axiom. It will turn out that this axiom is equivalent to SAMC. Here, as in the previous 
section, we will work in a locally cartesian closed lextensive and regular category £. 

Definition 4.1. By a class of small maps S in £ we will mean a class of maps in £ satisfying 
at least the following axioms: 

(SI) (Fullback stability) If the square 




is a pullback and / S «S, then also g & S. 

(52) (Covering) If a square as the one above is covering and g G S, then also / £ S. 

(53) (Collection) Any two arrows p:Y ^ X and f:X^A where p is a cover and / belongs 
to <S fit into a covering square 




where g belongs to S. 

A representation for a class of small maps 5 is a morphism tt: E ^ U £ S such that any 
morphism / € 5* is covered by a pullback of tt. More explicitly: any f-.Y^X^S fits into a 
diagram of the form 

Ym A >E 




where the left hand square is covering and the right hand square is a pullback. The class <S will 
be called representable, if it has a representation. 
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Definition 4.2. The reflection principle RP states that every map belongs to a representable 
class of small maps. 

Theorem 4.3. RP and SAMC are equivalent. 

Proof. We first show that RP implies SAMC. Suppose f:B^A belongs to a class of small 
maps <S with representation ir-.E^U. Form a covering square 




in which 

C = {{a,u,p): a€ A,u€U,p:Eu^ Ba}, 

D = {{a,u,p,e): {a,u,p) eC,eeEy,}, 

and the maps are the obvious projections. We will now show that it is a strong collection square 
as well. 

Reason in the internal logic: suppose c = {a,u,p) e C and t:Y ^ = Dc is a cover. 
Using the collection axiom we find a small S and a cover q-.S^Eu factoring through t. By 
representability, there is a cover of the form r; Eu' S with u' G U. Putting h: = qr and 
c' = {a,u',ph), we see that h is really a map Dc' = ^ £"„ = Dc over B; in addition, it 
factors through t because q does. 



In order to show that SAMC impUes RP, let /: Y 

D >^AxxY- 



X be a map fitting into a diagram 
-^Y 



C 



with the square on the left both covering and strong collection, while the one on the right is 
a puUback with an cover q at the bottom. Let <S be the class of maps g:T ^ S fitting into 
diagrams of the form 

• ¥D 




where the left hand square is covering and the right hand square is a puUback. Alternatively, 
we can say that g:T ^ S belongs to S iff the following statement holds in the internal logic: 

(Vs e S) (3c G C) {3p: Dc Ts)p is surjective. 

It is immediate that 5 is a class of maps satisfying (SI) and (S2). It also satisfies the collection 
axiom (S3); to show this we reason internally. Let q: E —» Z he a cover and Z be "small" (in 
the sense of <S), meaning that there is a c G C and a cover p:Dc — > Z. Take the following 
puUback: 

F »E 
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Using the strong collection square property, we find a c' £ C and a cover h: Dc' Dc factoring 
through r. Since Dc' is obviously small, we have shown that S satisfies (S3). 

So iS is a class of small maps. As it is representable by construction and contains /, the 
proof is finished. □ 

Remark 4.4. Although RP is reminiscent of REA, this result probably means that RP is a bit 
stronger. For although SAMC implies REA (see [30]), we would conjecture that the converse 
fails. 



5. The Axiom of Multiple Choice in ZF 



In this section we study AMC in the context of the classical set theory ZF. Set-theoretically, 
AMC is the following statement: 

For every set X there is a set of surjections {pi: Yi ^ X} onto X such that for 
every surjection q: Z ^ X there is an i G / and a function f:Yi~^Z such that 
Pi = q° f- 

The following result was already shown for strong AMC by Rathjen (see [34]). 
Theorem 5.1. In ZF, AMC implies that arbitrarily large regular cardinals exist. 

Proof. Let k be a cardinal and use AMC to find a family [pi. Bi ^ K\i € I) oi surjections onto 
K such that for any surjection onto k we find one in this family which factors through it. Put 
A = / + {0, 1}, Bo = 0, Bi = {0} and let 

be the obvious projection. In addition, write W = W{f) for the W-type associated to /. 
By transfinitc induction on W , we can now define a map m:W Ord as follows: 

m(supj(i)) — sup{m(t6) : b G Bi\, 
m(supo(i)) = 0, 
m(supi(i)) = m(i(0)) + l. 

Observe that: 

(1) lies in the image on m. 

(2) The image of m is closed under taking successor ordinals. 

(3) The image of m is closed under suprema of cardinality k: for ii (3 — s\Yp{a\) and 
ax € m(W) for every A G k, then 

(VA e k) {3w e W) m{w) = ax- 

By choice of {fi'. Bi — s> k | i G /) there now is an i G / and a function t: Bi ^ W such 
that 

(Vfe G Bi) m{tb) = ap^(^i,y 

Hence /3 = m(supj(t)). 

So if a = sup(to(W^)), then a is a limit ordinal of cofinality strictly greater than k. But since 
the cofinality of a limit ordinal is always a regular cardinal, we have found a regular cardinal 
whose size is strictly greater than k. □ 
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Corollary 5.2. AMC is unprovable in ZF. 

Proof. This follows from Theorem 15.11 and a celebrated result of Gitik [T7], saying ZF is con- 
sistent with the statement that all uncountable cardinals are singular. □ 

Remark 5.3. To construct his model of ZF in which all uncountable cardinals are singular, 
Gitik uses the existence of a proper class of strongly compact cardinals. It is known that large 
cardinal assumptions are necessary for that result; whether they are also necessary for refuting 
AMC is an open problem. 

Corollary 5.4. In ZF, AMC implies that every algebraic theory has free algebras. 

Proof. Follows from Theorem 15. II above and Proposition 2 on page 151 of jT5]. □ 

That every algebraic theory has free algebras is known not to be provable in ZF proper (see 
[T2] : of course, it is provable in ZFC). So this is an example of an interesting mathematical 
statement which can be proved using AMC, but is not provable in ZF. It would be interesting 
to see more statements of this kind. 



6. Examples of predicative toposes 

The previous section concludes our discussion of the Axiom of Multiple Choice. We will now 
turn to the theory of predicative toposes. As we explained in the introduction, we will define 
these as follows: 

Definition 6.1. A (strong) predicative topos is a IlW^-pretopos satisfying the (strong) Axiom 
of Multiple Choice. 

In this section we will mainly collect some examples of predicative toposes. Of course, the 
most interesting are the ones that are not toposes. 

Theorem 6.2. The category of setoids in MLTT is a strong predicative topos. 

Proof. In [29| Section 7] it is shown that the setoids form a IIVF-pretopos. Since in this category 
every map is covered by a choice map (see |301 Lemma 12.3]), it is a strong predicative topos 
by Proposition 13.71 □ 

As we said in Section 2, most examples are built using the theory of exact completions. 
Theorem 6.3. The ex/lex- completion of a HW -pretopos is a strong predicative topos. 

Proof. This follows from Theorem 4.7 in [4^ in combination with Proposition l2.5l and Proposition 
above. □ 



Remark 6.4. The previous theorem implies in particular that ex/lex-completion is a closure 
property of predicative toposes. In this respect they differ from toposes: an ex/lex-completion 
of a topos is a topos only if it has a generic proof (see [27 ). Examples of toposes without a 
generic proof can be found in |27[ 128] ; their exact completions are then examples of predicative 
toposes that are not toposes. 



For ex/reg-completions we have the following very useful result: 
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Theorem 6.5. If £ is a locally cartesian closed, lextensive and regular category which has all 
W-types and satisfies (strong) AMC, then its ex/reg- completion is a (strong) predicative topos. 

Proof. For ordinary AMC, this result was proved in the context of algebraic set theory in [51IH]- 
So it remains to show that SAMC is preserved by ex/reg-completion. We could prove this 
directly, but it can also be shown more elegantly using the equivalence of SAMC with RP. 

If / is a map in the ex/reg-completion, it is covered by one of the form yg, where y is the 
embedding of £ in £ex/reg- Let 5 be a class of small maps containing g in £. Then S determines 
a class of small maps S in £ex/regi whose elements are precisely those morphisms covered by 
ones of the form yh with h belonging to S (see [5] Lemma 5.7]). So / e iS and / belongs to a 
class of small maps. □ 

Theorem 6.6. (Strong) predicative toposes are closed under internal realizahility. 

Proof. For ordinary predicative toposes this was shown in the context of algebraic set theory in 
[5JIH]. So it remains to show that SAMC in preserved by realizability. We sketch an argument, 
relying on the theory developed in 6 and the equivalence of SAMC with RP. 

Let / be a map in the realizability category of £. Since this realizability category is the 
ex/reg-completion of the category of assemblies, / will be covered by a map g between as- 
semblies. Choose a class of small maps S va £ such that g becomes a display map between 
assemblies, and let S be the class of maps in the realizability category that are covered by the 
display maps. Then 5 is a class of small maps containing /. □ 

Recall that an object X is called subcountable if it is a quotient of a subobject of N. 
Theorem 6.7. The subcountable objects in the effective topos form a strong predicative topos. 

Proof. Recall that the subcountable objects coincide with the discrete ones and that the discrete 
objects that are also ^-i-separated are called the modest sets (see [19] and f31, Section 3.2.6]). 
Since every discrete object is covered by a ^-i-separated subobject of N (due to Shanin's 
Principle) and ^-i-separated objects are closed under subobjects, the discrete objects are the 
ex/reg-completion of the modest sets. So if suffices to prove that the modest sets satisfy all 
the hypotheses of Theorem 16.51 for that, see [5], with the validity of SAMC following from 
Proposition [3?8] and the results on projective modest sets in [2]. □ 

Clearly, the subcountable objects cannot form a topos: the subcountability of Pow(N) leads 
to a contradiction by Cantor's diagonal argument. 

Theorem 6.8. The ex/lex- completions of the category of topological spaces and the category of 
Tq -spaces are strong predicative toposes. 

Proof. To simplify the proof we first make a number of definitions (see [3]): first of all, let ACat 
be the category of algebraic lattices. An assembly over ACat is a triple (X, a, a) where X is 
a set, a is an algebraic lattice and a is a function which assigns to every x £ X an inhabited 
subset of cr. A morphism /: {X, a, a) {Y, r, f3) is a function f: X ^ Y for which there is a 
morphism r: tr — ^ t in ACat such that 

(Vx e X) (Vn G a{x)) rn G l3{fx) 

(we will say that r tracks /). The resulting category will be denoted by Asm[ACat]. An 
assembly {X, cr, a) will be called modest, if a maps distinct elements to disjoint subsets of a. 
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We will write A4od[ACat] for the full subcategory of Asm[ACat] whose objects are the modest 
assemblies over ACat (this category is equivalent to the category of equilogical spaces) . 

It is easy to see that in both categories the projective objects are those assemblies {X, a, a) 
for which a{x) is always a singleton, the projectives are closed under finite limits and that 
every object is covered by such a projective. Since the full subcategories on the projectives 
are equivalent to the category of topological spaces and Tg-spaces respectively (see [H]), it 
follows from Corollary 12.71 that the ex/lex-completion of the category of topological spaces is 
equivalent to the ex/reg-completion of Asm[ACat\, while the ex/lex-completion of the category 
of Tg-spaces is equivalent to the ex/reg-completion of Mod[ACat]; so it suffices to prove that 
both Asm[ACat] and J^od[ACat] satisfy the hypotheses of Theorem 16.51 

Using that ACat is cartesian closed and has finite disjoint sums, it is easy to see that both 
Asm[ACat] and M.od[ACat] are categories which are locally cartesian closed, lextensive and 
regular. In addition, they satisfy SAMC because of Proposition |XH1 So it remains to show that 
both categories have W-types. We will just outline the construction, leaving verifications to 
the reader. 

The key observation is that ACat is a category of domains in which one can prove that 
functors of the form 

F{X) ^ px (a ^ X) 

have initial algebras. So if /: {B, a, fi) — s- {A, p, a) is a niorphism between assemblies, let fj, be 
an initial algebra for F and let 

s: p X {a ^ ii) ^ fi 

be the algebra map. Now write W = W{f) for the W-type associated to / in Sets, and define 
by transfinite recursion: 

6: W{f) — >■ p: sup^(t) i— >• { s{x, y) : x ^ V'-O' ^ 1^ tracks t }. 

li V = {w G W : S{w) is inhabited }, then (F, p, S) is the W-type associated to /. Moreover, if 
(B, cr, (3) and {A, p, a) are modest, then so is {V, /i, S). □ 

Remark 6.9. Both exact completions were already known to be locally cartesian closed preto- 
poses (see llj). It also follows from known results that neither of the two predicative toposes 
can be a topos: for a proof that the ex/lex-completion of the category of topological spaces is 
not a topos, see [22]. The ex/lex-completion of the category of To-spaces cannot be a topos, 
because it is not well-powered: in fact, the category A4od[ACat] already fails to be well-powered 
(see [3]), so the same applies to its ex/reg-completion. 

7. Sheaves for predicative toposes 

As we explained in the introduction, a crucial result in formal topology says that set- 
presented formal spaces can be constructed using inductive definitions. As predicative toposes 
should be an environment in which one can do formal topology, it will be important to show 
that one can perform this construction internally to a predicative topos. But we can do more: 
inductively generated formal spaces are a special case of Grothendieck sites constructed from 
general sites. And also the more general construction can be formalised in a predicative topos, 
as we will now explain. 

We have decided to follow [30] in the formalisation of the notion of a site. So here the 
basic categorical structure of an internal site consists of an internal category C together with 
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a collection of covering families Cov(C) for every object C of C. This is formalised by a 
commutative square of the form 

Cgv^^Ci 

(1) cod 

Gov — - — > Co , 

where Ci is the object of arrows and Co the object of objects of the internal category C, while 
cod is the codomain map. So any U E Cov(C) gives rise to an indexing set Covu, indexing 
a family of arrows all with codomain C. Such a covering family U will therefore typically be 
denoted by {aii Ci ^ C \ i G I), where / is the indexing set. (Here it is to be understood that 
Ui can be equal to aj for different i and j.) 

For a site, the following axiom should hold in the internal logic: 

(C): For any covering family (a^: Ci — C | i G /) of C and any arrow f:D-^C, there 
exists a covering family {/Sj-.Dj D\j <E J) such that every composite f/3j factors 
through some ai. 

Sites are the right context to formulate the notion of a sheaf. An (internal) presheaf V on 
an internal category C consists of an indexed family {P(C)}ceCo (given by a map V — > Co), 
together with an action by Ci. The idea is that any p G 'P{C) is acted on by a morphism 
/: D — >■ C in Ci to determine an element p ■ f € V{D), where this action is subject to the 
following two equations (whenever they make sense): 

p-\d = p, 

{p-f)-g = p-{fg)- 

Now assume C is the underlying category of an internal site (C, Gov), and let V he a presheaf 
on C. A compatible family on an object C S Co consists of a covering family (a^: Ci ^ C \ i € I) 
of C, together with for every i G I an element pi € V{Ci), in such a way that for any pair 
i,j G / and any pair of maps f,g G Ci for which we have Uif — ajg the equation Pi ■ f — Pj ■ g 
is satisfied. An element p G 'P(C) will be called the amalgamation of this compatible family, in 
case p ■ ai — pi for every i E I. The presheaf V will be called a sheaf when every compatible 
family has a unique amalgamation. 

The next definition formulates different notions of a site. 

Definition 7.1. Let (C, Gov) be a site. 

(1) It will be called a Grothendieck site when it satisfies the following closure conditions: 

(M): For any object C, there is a covering family U G Cov(C) such that (id^: C — s- 
C) G U. 

(L): Whenever there are a covering family [ai.Ci -> C | i G /) of C and families 
{Pij: Cij > Ci \j £ li) covering Ci for every i E I, there is a family (7;: Di 

C \ l E L) such that every 7; factors through some aiPij. 

(2) It will be called a (strong) collection site, if ([1} is a (strong) collection square. 

As Johnstone explains in [20], in topos theory (M) and (L) are closure conditions that "might 
just as well be there" , but are not essential to the notion of a site. This is backed up by the 
result that in a topos there is for every internal site a Grothendieck site leading to an equivalent 
category of sheaves (if that happens, we say that the sites are equivalent). The idea behind 
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the construction of the Grothendieck site is to generate it inductively by closing off under the 
conditions (M) and (L). In a predicative topos, we do have W- types and the inductive definition 
does not present any problems; we do have some choice issues, however, for which we do seem 
to need that we start with a collection site. It is fortunate, then, that we can show (compare 
Lemma 8.3 in [50]): 

Lemma 7.2. Let £ be a (strong) predicative topos. Then for every internal site C in £ there 
exists an equivalent (strong) collection site. 



Proof. If we have an internal site in £ represented by 

Gov " > Ci 
^ cod 
Gov — - — > Co 



and £ satisfies (strong) AMG, we can apply it to the map cj) to obtain 



Gc 



cod 



D 



Gov 



where the left square is both covering and a (strong) collection square. The idea is to replace 
the original site by the one represented by the outer rectangle. It is easy to see that this defines 
an equivalent site which is also (strong) collection. □ 

Proposition 7.3. Let £ be a (strong) predicative topos. For every (strong) collection site 
(C,Gov) in £ there exists an equivalent Grothendieck (strong) collection site (C,GOV). 

Proof. The idea is to build GOV as the object inductively generated by the following inference 
rules: 

{af.C,-^C\ieI)e Gov(C) V, e GOV(C,) 
(idc-C^C) e GOV(C) (a^ o /3 | /3 e F,) e GOV(C). 

To show that one can achieve this, define an endofunctor F: £/Cq ^ £ /Cq as follows (C G Cq): 

{FX)c^l+ J2 n ^dom(™W)- 
;7eGov(c) igCov^ 

This is an example of what Gambino and Hyland in |16j call a dependent polynomial functor. 
They show that, in the presence of W-types, these have initial algebras, so we may define the 
new object of covering families GOV as the initial algebra for F; as it is a fixed point, it will 
satisfy (C € Cq): 

GOV(C) = 1 + J2 n COV(dom(m(i))). 
c/gGov(c) ig Gov ^, 

In addition, initial algebras allow definition by recursion on their elements and this we will 
use to define the new object GOV over GOV and the new arrow M, thereby completing the 
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definition of tlie site (C, GOV): 

COV^^Ci 

cod 

GOV > Co. 

Elements V in GOV (over C G Co) arc cither * (the unique element of 1) or of the form swpu{t), 
where U G Gov(C) and tiCavu — )■ GOV. So we may define COVy by recursion on V as: 

GOV* = 1, 

The definition of M runs as follows. The unique element of GOV * is sent to Ic-C ^ C. An 

element in GOV snp^ ii\ is of the form {i,k), with i e Gov ^r and k e GOV ^^,-) . Such an element 

(i, k) is sent to m{i) o M{k). 

We will now outline why the constructed objects have the desired properties. First, we need 
to show that (C, GOV) is a Grothendieck site. It is obvious that GOV now satisfies the rule 
(M). By induction on the construction of the covering family V G COV(C), one can show that 
the covering families in GOV are closed under (G) and (L), using that (C,Gov) is a collection 
site. We will give the argument for (G), the proof of (L) being similar. liU = (idc: C — >■ C), 
then U clearly satisfies (G), so it remains to consider the case where U is obtained by the second 
inference rule. So let V = Gov(C) be of the form (a^ : — C | i e J) and assume that the 
covering families Vi € GOV(Ci) are closed under (G). Now let /:£> ^ C be any map in the 
internal category C. I need to show that there is an U' <E COV(D) such that for any g e U'. 
the arrow fg factors through some a^/J with (3 £ Vi. As (C,Gov) is a site, there is a covering 
family {SjiDj D\j G J) £ Cov{D) such that every f6j factors through some a^. Using that 
the Vi have the property (G), this means that the following holds in the internal logic of £: 

For all j e J, there is an i G 7, a morphism h: Dj — >■ Cj and a covering family 
V e GOV(Dj) such that: (1) fSj = aih, and (2) every h/3' with P' e V factors 
through some /3 with (3 G Vi. 

Here we use that (C, Gov) is a collection site: so there is a covering family (7^: D). D\k £ 
K) e Gov(£') together with an map p: K ^ J satisfying Spk = 7fc for all k G K, such that 
appropriate i, h and V' are given as a function of k G K: call these ik, hk and V^. One can 
now build the desired U' G COV{D) by applying the second inference rule to {-jk- Dk ^ D \ k G 
K) G Coy{D) and V^ G COYiDk). Then every g G U' is of the form jkl3' with /?' G V^, and 
hence f^kf3' — ai^^hkP' factors through ai^i_f3 for some (3 G Vi^^. This proves that (C, GOV) is 
a site. As said, the argument that it satisfies (L), and is therefore a Grothendieck site, is very 
similar. 

The proof that (C, GOV) is a (strong) collection site also goes along very similar lines. We give 
the construction, leaving verifications to the reader. Let V = {'Jj-Cj C\j G J) G GOV(C), 
and assume: 

Vj gJ3x GXip{j,x). 

We need to show that there exists another covering family V = {Sk'. Ck ^ C \ k G K) of V 
such that X can be given as a function of k. The argument proceeds by induction on the 
construction of V. The statement is trivial when V = (\dc-C — >■ C), so assume that V has 
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been built by the second inference rule, meaning that there are (a^: — > C | i G /) G Cov(C) 
and i^j-.Cj -^Ci\j GJi)€ COV(Ci) such that 

V = {a^Pj \ iel,j e J^}. 

By induction hypothesis, the following statement is true in the internal logic of £: 

For all i S /, there exists an element V = {ek'-Ck ^ C.t\k e K) e COV(Ci) 
together with a map (cover) p: K ^ Ji and a function g:K^X such that for 
ah k&K: (1) = Efc and (2) ip{{i,pk), gk). 

Since (C, Gov) is a (strong) collection site, there is a covering family {rji'.Ci — > C\l G L) G 
Cov(C) and a map (cover) r: L ^ I such that ari — rji and appropriate V, p and 5 are given 
as a function oi I G L. To obtain the right covering family, we apply the second inference rule 
to {rif. Ci C \ I e L) and the Vi . 

It remains to check that the sites (C, Gov) and (C, GOV) are equivalent. This is comparatively 
easy: if is a sheaf with respect to Gov, one shows that it satisfies the sheaf condition for V G 
GOV(C) by a straightforward induction on the generation of V. Gonversely, every {ai.Ci — > 
C I i G /) G Gov(C) also occurs as an element of GOV(C) (use the second inference rule with Vi 
consisting solely of the arrow idcj, so anything that is a sheaf with respect to GOV is certainly 
also a sheaf with respect to Gov. □ 



To summarise: 

Theorem 7.4. Let £ he a (strong) predicative topos. Then every site in £ is equivalent to a 
Grothendieck (strong) collection site. 

This we can use to establish our final closure property of predicative toposes: 
Theorem 7.5. (Strong) predicative toposes are closed under internal sheaves. 

Proof. It is well-known that the category of internal presheaves has finite limits and is locally 
cartesian closed (see 29,, for example). The same applies to internal sheaves, because finite 
limits and exponentials in sheaves are computed as in presheaves. 

To show that the internal sheaves form a pretopos, we first observe that, in view of the 
previous theorem, we may assume that we are taking sheaves over an internal Grothendieck 
collection site. In that case, [301 Lemma 8.1] tells us that a sheafification functor, a left adjoint 
to the inclusion of presheaves in sheaves, exists (that argument also works for collection sites 
that are not strong). Hence sums and quotients in sheaves can be constructed by sheafifying 
sums and quotients in presheaves. 

Furthermore, to show that the category of sheaves has W-types, we use AMG as in [71 
Theorem 4.21]. (It is clear from the proof that ordinary AMG suffices.) 

Finally, that AMG is inherited by sheaves is shown in detail in |8l Section 5] ; for strong AMG 
that was shown in [30l Section 10]. In fact, the latter proof can be simplified considerably by 
using the equivalence of SAMG with RP, but we will not go into the details here. □ 
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8. Conclusion and open questions 

As we said in the introduction, we hope that this paper can form a starting point for future 
work on predicative topos theory. We will finish it by indicating some directions for future 
research. 

(1) We have established that predicative toposes are closed under internal realizability and 
sheaves. But there arc more closure properties one could have a look at, such as glueing, 
forming coalgebras for a cartesian comonad and taking filter quotients. Some results 
in this direction have been obtained for nVF-pretoposes (see 13]). The question is 
whether these results still go through now that we have added AMC. 

(2) In view of the results in Section 5, it would be interesting to see whether algebraic the- 
ories have free algebras internally in a predicative topos. (This question was originally 
posed to us by Alex Simpson.) We expect that they do. More generally, it would be an 
interesting project to investigate which inductively defined structures and which initial 
algebras exist in a predicative topos. 

(3) One would like to have more examples of predicative toposes. Possible candidates are 
the ex/reg-completions of various quasitoposes, where one would hope to be able to 
further exploit Theorem l6.5l in our opinion, this would be especially interesting for the 
modified assemblies (see [3T]). One could also try to put the last couple of examples 
from Section 6 in the context of the theory of typed peas (see [23, and ,22; ), or in 
the framework of [TU]. In this way one should also be able to find new examples of 
predicative toposes that are not toposes. 

(4) Given the recent interest in homotopy type theory, it is natural to ask what is the 
connection to the notion of a predicative topos. For example, do the hSets (the types 
of h-level two) in homotopy type theory form a predicative topos? (This question is 
due to Bas Spitters.) 
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